Optimization of NIDS placement for protection of intercommunicating critical infrastructures

Rami Puzis, Marius David Klippel, Yuval Elovici, Shlomi Dolev

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

13 Scopus citations

Abstract

Many Critical Infrastructures (CI) use the Internet as a means of providing services to citizens and for dispatching their own transactions. CIs, like many other organizations connected to the Internet, are prone to cyber-attacks. The attacks can originate from their trusted customers or peer CIs. Distributed network intrusion detection systems (NIDS) can be deployed within the network of national Network Service Providers to support cyber-attack mitigation. However, determining the optimal placement of NIDS devices is a complex problem that should take into account budget constraints, network topology, communication patterns, and more. In this paper we model interconnected CIs as a communication overlay network and propose using Group Betweenness Centrality as a guiding heuristic in optimizing placement of NIDS with respect to the overlay network. We analyze the effectiveness of the proposed placement strategy by employing standard epidemiological models and compare it to placement strategies suggested in the literature.

Original languageEnglish
Title of host publicationIntelligence and Security Informatics - First European Conference, EuroISI 2008, Proceedings
Pages191-203
Number of pages13
DOIs
StatePublished - 1 Dec 2008
Event1st European Conference on Intelligence and Security Informatics, EuroISI 2008 - Esbjerg, Denmark
Duration: 3 Dec 20085 Dec 2008

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5376 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference1st European Conference on Intelligence and Security Informatics, EuroISI 2008
Country/TerritoryDenmark
CityEsbjerg
Period3/12/085/12/08

Keywords

  • Communication infrastructure protection
  • Epidemic models
  • NIDS placement

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'Optimization of NIDS placement for protection of intercommunicating critical infrastructures'. Together they form a unique fingerprint.

Cite this